Skip to content

feat: add provider-backed rate limiting boundary - #3

Merged
ZhiXiao-Lin merged 1 commit into
mainfrom
codex/rate-limit-provider
Jul 20, 2026
Merged

ZhiXiao-Lin merged 1 commit into
mainfrom
codex/rate-limit-provider

Conversation

@ZhiXiao-Lin

Copy link
Copy Markdown
Contributor

Summary

  • expose a public async RateLimitProvider contract for atomic shared-budget acquisition
  • keep the existing process-local behavior through InMemoryRateLimitProvider
  • scope SHA-256 subject digests by stable policy ID so plaintext header values and bearer credentials do not cross the provider boundary
  • reject provider errors, invalid policies, and conflicting settings without bypassing the guard
  • document the provider boundary and its intentionally limited scope

Scope

This delivers the provider-backed distributed rate-limiting boundary requested by the Cloud C0 work. It does not select a distributed backend or implement the remaining streaming cancellation, backpressure, authorization metadata, graceful-drain, or telemetry work.

Progresses #1

Validation

  • cargo fmt --all -- --check
  • cargo test --features security --test security
  • cargo test --features security --lib security::rate_limit
  • cargo test --all-features --locked
  • cargo clippy --all-targets --all-features --locked -- -D warnings
  • git diff --check

@ZhiXiao-Lin
ZhiXiao-Lin merged commit ef0d6b0 into main Jul 20, 2026
1 check passed
@ZhiXiao-Lin
ZhiXiao-Lin deleted the codex/rate-limit-provider branch July 20, 2026 03:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant